OpenAI Bug Disclosure Backlash: Security Community Slams CISO Before Reconciliation

Security researcher S1r1u5 (of team Hacktron) used Codex on cloud to verify a vulnerability granting access to OpenAI's internal monorepo, claiming the ability to laterally move toward model weights, datasets, and training recipes — but deliberately downloaded nothing sensitive, proved access with a harmless PR, stopped there, and followed responsible disclosure. Per their account, however, OpenAI's disclosure process was "a nightmare": the bounty amount ($6,500) wasn't the issue, but they had to consult lawyers and eventually turn to journalists to get things moving. Meanwhile, OpenAI's CISO (a former Palantir employee) was reported to have pushed for suing the researcher, sparking community mockery of OpenAI for "embracing the security community" in words while wielding legal threats in practice. Per LiveOverflow, the CISO has since reached out to apologize and the two sides reconciled.

Confirmed

Unconfirmed

Why it matters

2026-09-19 ~ 2026-09-21 · 14 related posts

Full story(4 episodes)→

Primary sources